Freeciv is a free, open-source implementation of the Civilization strategy game that supports multiplayer play through networked servers, creating an attack surface around game-state synchronization and network command handling. Its vulnerability profile centers on a single product and clusters around resource-handling and input-validation weaknesses—including buffer overflows, uncontrolled resource consumption, OS command injection, and improper input validation—that are characteristic of network protocol parsers in game engines; these disclosures have a strong tendency toward public exploit availability. Defenders and server operators should treat Freeciv instances as potential pivoting points if exposed to untrusted networks, particularly those hosting multiplayer servers; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freeciv over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6083HIGH Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet. | Jan 23, 2020 | 7.5 | 40 | NO | YES |
CVE-2010-2445HIGH freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the | Jul 8, 2010 | 10.0 | 29 | NO | NO |
CVE-2022-39047HIGH Freeciv before 2.6.7 and before 3.0.3 is prone to a buffer overflow vulnerability in the Modpack Installer utility's handling of the modpack URL. | Aug 31, 2022 | 8.8 | 28 | NO | NO |
CVE-2012-5645HIGH A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, | Dec 30, 2019 | 7.5 | 26 | NO | NO |
CVE-2006-0047MEDIUM packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values. | Mar 7, 2006 | 5.0 | 25 | NO | YES |
CVE-2006-3913HIGH Buffer overflow in Freeciv 2.1.0-beta1 and earlier, and SVN 15 Jul 2006 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary cod | Jul 28, 2006 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freeciv.
Media articles that mention a CVE ID that affects a product developed by Freeciv — matched by CVE ID, not by vendor name.